Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

FortiBleed: A Credential-Harvesting Campaign that Exposed the Attackers Themselves


FortiBleed, a sophisticated cyber attack campaign, has compromised an astonishing 86,644 Fortinet firewalls across 194 countries, leaving a trail of digital devastation in its wake. The attack, which began in recent days, has exposed the attackers themselves due to their poor operational security, providing investigators with a rare opportunity to understand the inner workings of the campaign.

  • FortiBleed, a sophisticated cyber attack campaign, has compromised 86,644 Fortinet firewalls in 194 countries, exposing attackers' poor operational security.
  • The campaign targets Fortinet firewalls, exploiting a vulnerability in the system's SSL VPN portals, using credential stuffing and automated scanning to gain access to sensitive data.
  • The attackers sell the gained access to initial access brokers, which can lead to ransomware attacks and further encryption.
  • Mitigation advice includes restricting external management access, removing internet-facing administration, and using phishing-resistant MFA for remote access and admin accounts.
  • The campaign highlights the importance of operational security and the need for organizations to stay vigilant against sophisticated attacks.



  • FortiBleed, a sophisticated cyber attack campaign, has compromised an astonishing 86,644 Fortinet firewalls across 194 countries, leaving a trail of digital devastation in its wake. The attack, which began in recent days, has exposed the attackers themselves due to their poor operational security, providing investigators with a rare opportunity to understand the inner workings of the campaign.

    The FortiBleed campaign, which is believed to have been launched by a group of skilled hackers, targets Fortinet firewalls, exploiting a vulnerability in the system's SSL VPN portals. Once inside, the attackers use a combination of automated scanning and credential stuffing to gain access to sensitive data. The campaign's attackers use stolen credentials, which were either leaked or reused, to gain access to the targeted firewalls.

    The FortiBleed campaign is particularly noteworthy for its use of a sophisticated technique called credential stuffing. This involves using a combination of automated scanning and password spraying to crack the passwords of compromised accounts. The attackers use a GPU-accelerated cluster to run Hashcat and Hashtopolis, turning stolen hashes into usable plaintext passwords at an unprecedented scale.

    The attack chain is further complicated by the use of proxy nodes and beacon relays, which allow the attackers to obfuscate their presence and avoid detection. The attackers also create new admin accounts on the firewall to maintain access and move through the network, mapping Active Directory and using password spraying to find accounts with higher privileges.

    The campaign's aftermath is just as concerning as the initial breach. The attackers have been deleting or changing passwords on existing accounts, which means that some victim organizations are finding themselves completely locked out of their own Fortinet devices. This has resulted in significant disruptions to the affected organizations' operations, with some unable to even start remediation without extra recovery steps beyond a normal patch-and-reset.

    In a twist, the attackers have been selling the access gained through FortiBleed to initial access brokers supplying ransomware affiliates, specifically naming INC/Lynx and Payload ransomware as currently active buyers. This means that a credential-stuffing campaign against a firewall today can turn into an encrypted network tomorrow, with someone else entirely doing the encrypting.

    The mitigation advice from the FBI and the U.S. Secret Service is straightforward but highlights the need for basic security hygiene. The attackers recommend restricting external management access to trusted systems or using a local-in policy. Better still, removing internet-facing administration completely and ending all active admin and VPN sessions, resetting passwords on internet-facing systems, and requiring phishing-resistant MFA for every remote access and admin account are key steps to prevent similar attacks.

    The use of legacy SHA-256 password storage made large-scale password cracking much easier, and Fortinet recommends using PBKDF2 for administrator passwords on FortiOS 7.2.11 and later.

    In conclusion, the FortiBleed campaign is a stark reminder of the importance of operational security and the need for organizations to stay vigilant against even the most sophisticated attacks. As the attackers' poor operational security exposed their backend infrastructure, it also provided investigators with a unique opportunity to understand the inner workings of the campaign.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/FortiBleed-A-Credential-Harvesting-Campaign-that-Exposed-the-Attackers-Themselves-ehn.shtml

  • https://securityaffairs.com/200558/cyber-crime/fortibleed-hit-86000-firewalls-by-exploiting-something-nobody-can-patch-away.html

  • https://www.ic3.gov/CSA/2026/261006.pdf


  • Published: Wed Oct 7 10:02:14 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us